CVE-2015-0016
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2015-0016 is a directory traversal vulnerability affecting the TS WebProxy component in various Microsoft operating systems, including Windows Vista SP2, Windows 7 SP1, and others. This issue allows remote attackers to manipulate the pathname of an executable file in a crafted manner, resulting in a privilege escalation from Low Integrity to Medium Integrity. The exploit enables attackers to gain elevated access, potentially leading to further system compromises. The vulnerability, also known as the "Directory Traversal Elevation of Privilege Vulnerability," affects Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold, and Windows RT Gold and 8.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 7
- Microsoft Windows 8.1
- Microsoft Windows Vista
- Microsoft Windows Server 2008
- Microsoft Windows Server 2012
Affected Vendors
- Microsoft